PRIVACY POLICY
Welcome to [Website Name or Brand]. At [Full Name or Company Name of Owner], we are committed to protecting your privacy and personal data. This Privacy Policy describes how we collect, use, store, share, and protect the personal information you provide to us through our website [Website URL] (hereinafter, the "Website").
We recommend that you read this policy carefully before using our services or providing us with your data.
1. DATA CONTROLLER
The controller responsible for the processing of personal data collected through this Website is:
- Identity: [Full Name of the individual or Company Name]
- Tax ID Number (NIF/CIF): [Tax Identification Number]
- Registered Office: [Full Postal Address]
- Contact Email for Privacy Matters: [Specific email address for privacy issues, e.g., privacy@yourwebsite.com]
- Telephone: [Phone number]
- Data Protection Officer (DPO) (if applicable): [If you have a mandatory or voluntary DPO, provide their contact details here or how to contact them. If not, state "Not applicable"]
2. PRINCIPLES APPLIED IN DATA PROCESSING
In processing your personal data, we will apply the following principles in accordance with the requirements of the GDPR and LOPDGDD:
- Principle of lawfulness, fairness, and transparency: We will always require your consent for the processing of your personal data for one or more specific purposes about which we will inform you beforehand with absolute transparency, or we will process your data under another valid legal basis.
- Principle of data minimization: We will only request data that is strictly necessary in relation to the purposes for which we require it.
- Principle of storage limitation: Data will be kept for no longer than necessary for the purposes of the processing; depending on the purpose, we will inform you of the corresponding retention period.
- Principle of integrity and confidentiality: Your data will be processed in a manner that ensures appropriate security of the personal data and guarantees confidentiality. We take precautions to prevent unauthorized access or misuse of our users´ data by third parties.
3. PERSONAL DATA WE COLLECT AND HOW WE OBTAIN IT
We collect different types of personal information depending on your interaction with our Website:
- Identification data: First name, last name, email address, phone number [Add others if applicable: postal address, etc.] – collected through [Specify how: contact forms, user registration, newsletter subscription, purchase process, etc.].
- Connection and Browse data: IP address, browser type, operating system, pages visited, visit duration, etc. – collected automatically through cookies and similar technologies (See our [Link to Cookie Policy]).
- Academic and professional data: [If you have a "Work with us" form] Information included in your curriculum vitae (CV).
- Financial or transaction data: [If you have an online store or payments] Data necessary to process payments (e.g., card details - managed directly by our secure payment gateway, billing details). We [Indicate whether you store any payment data, even partial or tokenized].
- Other data: [Specify any other type of data collected, e.g., geolocation data with consent, images, etc.]
4. PURPOSES OF PROCESSING
We process your personal data for the following purposes:
- To manage your registration as a user of the Website.
- To manage the contracting of products or services offered through the Website, including order and payment management.
- To respond to your inquiries, requests, or petitions made through the available contact channels.
- To send you commercial communications, newsletters, promotions, or information about our products or services, provided you have given your explicit consent.
- To manage your application in personnel selection processes [If applicable].
- To improve the quality and operation of the Website, perform statistical analysis, and market research [Preferably with aggregated or anonymized data].
- To ensure the security of the Website and prevent fraud.
- To comply with legal obligations [E.g.: tax, accounting].
5. LEGAL BASIS FOR PROCESSING
The legal basis that allows us to process your personal data depends on the purpose for which we process it:
- Consent (Art. 6(1)(a) GDPR): For sending commercial communications/newsletters, installing non-essential cookies, collecting data for specific purposes that we inform you about and for which we request your explicit permission (e.g., participation in contests, publishing testimonials). You can withdraw your consent at any time.
- Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR): To manage your user registration, process your purchases or orders, provide the services you request from us.
- Compliance with a legal obligation (Art. 6(1)(c) GDPR): To comply with legal obligations applicable to us (e.g., tax regulations, consumer law, etc.).
- Legitimate interest (Art. 6(1)(f) GDPR): To respond to your inquiries, ensure website security, perform internal analysis to improve our services (always balancing against your rights and freedoms), or send you commercial communications about products similar to those you have already contracted (direct marketing to existing customers, always allowing opt-out).
6. DATA RETENTION PERIOD
We will keep your personal data only for the time necessary to fulfill the purpose for which it was collected and to determine any possible liabilities that might arise from said purpose and data processing. The criteria we use are:
- Customer/registered user data: As long as the contractual or commercial relationship is maintained, and subsequently for the legally required periods (e.g., tax, commercial deadlines).
- Data for sending commercial communications: Until you withdraw your consent.
- Inquiry data: For the time necessary to respond and follow up.
- Candidate data: For [Specify period, e.g., 1 year] for selection processes, unless you indicate otherwise.
- Cookie data: As specified in our [Link to Cookie Policy].
Once the periods expire, the data will be securely deleted or anonymized.
7. DATA RECIPIENTS (DISCLOSURES AND DATA PROCESSORS)
Your personal data will not be disclosed to third parties without your consent, except where there is a legal obligation.
However, to provide our services, we need to share your data with certain providers (data processors) who process it on our behalf and following our instructions, ensuring confidentiality and security:
- Technology service providers (hosting, web maintenance).
- Payment service providers [Specify which one(s), e.g., Stripe, PayPal, RedSys].
- Courier and logistics companies [If applicable].
- Email marketing platforms [Specify which one(s), e.g., Mailchimp, Sendinblue].
- Web analytics service providers [E.g., Google Analytics].
- Tax, accounting, legal advisors [If applicable].
Some of these providers may be located outside the European Economic Area (EEA). In such cases, we ensure that international data transfers are carried out with adequate safeguards (e.g., Standard Contractual Clauses, Adequacy Decisions, etc.). You can request more information about these safeguards by contacting us.
8. USER RIGHTS
As the data subject, you have the right to:
- Access your personal data.
- Request the rectification of inaccurate data.
- Request the erasure of your data (right to be forgotten), when, among other reasons, the data is no longer necessary for the purposes for which it was collected.
- Request the restriction of processing of your data, in which case we will only keep it for the exercise or defense of claims.
- Object to the processing of your data for reasons related to your particular situation, or for direct marketing purposes.
- Request data portability in a structured, commonly used, and machine-readable format, to transmit it to another controller.
- Withdraw consent given at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
- Not be subject to automated individual decision-making, including profiling, which produces legal effects concerning you or similarly significantly affects you.
9. HOW TO EXERCISE YOUR RIGHTS
You can exercise your rights free of charge by sending a written communication, attaching a copy of your ID card or equivalent identification document, to:
- Email: [Specific email address for privacy]
- Postal Address: [Full Postal Address]
Clearly indicating the right you wish to exercise.
10. RIGHT TO LODGE A COMPLAINT WITH THE SUPERVISORY AUTHORITY
If you believe that the processing of your personal data infringes applicable regulations, you have the right to lodge a complaint with the competent Supervisory Authority, in Spain, the Spanish Data Protection Agency (AEPD) - www.aepd.es.
11. SECURITY MEASURES
We have adopted the necessary technical and organizational measures to guarantee the security of your personal data and prevent its alteration, loss, unauthorized processing, or access, taking into account the state of technology, the nature of the stored data, and the risks to which they are exposed. [You can mention some generic measures if desired, e.g., use of SSL certificates, access controls, backups, etc., but without giving excessive detail that could compromise security].
12. ACCURACY AND VERACITY OF THE DATA PROVIDED
The user is solely responsible for the veracity and correctness of the data provided, exonerating [Owner´s Name or Brand] from any responsibility in this regard. Users guarantee and are responsible, in any case, for the accuracy, validity, and authenticity of the personal data provided, and undertake to keep them duly updated.
13. PROCESSING OF DATA OF MINORS
Our services are generally not directed at children under 14 years of age. If you are under that age, please do not register or provide us with personal information without the consent of your parents or legal guardians. If we detect that we have collected data from a child under 14 without such consent, we will proceed to delete that information as soon as possible. [Adjust the age if your target audience DOES include minors and explain how you obtain parental consent].
14. CHANGES TO THE PRIVACY POLICY
We reserve the right to modify this policy to adapt it to new legislation or jurisprudence, as well as industry practices. In such cases, we will announce the changes introduced on this page reasonably in advance of their implementation. We recommend reviewing this policy periodically.
Last updated: [Date of last revision]